Detection rules › Splunk
Conhost.exe Kernel call (Sysmon)
conhost. exe ForceV1 asks for information directly from the kernel space, conhost connects to the console application. Usecase Identifies potentially suspicious Conhost execution paired with additional processes
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Execution | |
| Stealth |
References
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Sysmon | Event ID 1: Process creation |
Rule body
id: '5541.17145'
title: Conhost.exe Kernel call
description: 'conhost. exe ForceV1 asks for information directly from the kernel space,
conhost connects to the console application. Usecase Identifies potentially suspicious
Conhost execution paired with additional processes. - Software Association: Trojan.Killdisk/HermeticWiper,
Snatch'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_sysmon` ("EventCode=1" OR "<EventID>1<")
NOT (TERM(usoclient.exe) OR TERM(devicecensus.exe) OR TERM(ProgramData) OR "Program
Files" OR "wmiprvse.exe") | regex process="^\S+\s" | table _time, host, user, process,
process_*, parent_*, signature_id | bin span=1s | stats values(*) as * by _time,
host | regex process="conhost.exe 0xffffffff -ForceV1"| where mvcount(process)>1 '
techniques:
- defense-evasion:indirect command execution
- execution:command and scripting interpreter
- defense-evasion:exploitation for defense evasion
technique_id:
- T1202
- T1059
- T1211
data_category:
- Windows Sysmon
references:
- https://medium.com/@clermont1050/covid-19-cyber-infection-c615ead7c29
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_sysmon` ("EventCode=1" OR "<EventID>1<") NOT (TERM(usoclient.exe) OR TERM(devicecensus.exe) OR TERM(ProgramData) OR "Program Files" OR "wmiprvse.exe")
Stage 2: regex
| regex process="^\S+\s"
Stage 3: table
| table _time, host, user, process, process_*, parent_*, signature_id
Stage 4: bucket
| bin span=1s
Stage 5: stats
| stats values(*) as * by _time, host
Stage 6: regex
| regex process="conhost.exe 0xffffffff -ForceV1"
Stage 7: where
| where mvcount(process)>1
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
process | regex_match |
| field:"CommandLine" kind:regex_match |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | "EventCode=1" |
| 1 | "<EventID>1<" |